Re: splashd Not Redirecting
"Wilson Hernandez - MSD, S. A." <[email protected]> Tue, 18 Nov 2008 19:52:09 -0400
| Newsgroups | gmane.network.nocat |
|---|---|
| Organization | MSD, S. A. |
| Message-ID | <[email protected]> |
Colin,
I am running the gateway on Debian Etch, no radius server. Receiving
wireless and wired connections from a Linksys Router (WRT54G) with
dd-wrt but, this router is not running nocat, Can it be run like this?
I do not need authentication of any type only a splash page where user
must accept an agreement and proceed to the Internet.
When I try to access the internet from the LAN I get this (It captures
but it doesn't get redirected to the page the user first requested):
Message: Read 42 config items from /usr/local/etc/nocat.conf
Message: initializing static splash page
Message: Got command /usr/local/libexec/NoCatSplash/initialize.fw from
action ResetCmd
Message: starting main loop
Message: Captured peer 192.168.2.100
Message: Splashed peer 192.168.2.100
Message: Checking peers for expiration
Message: Checking peers for expiration
Message: Checking peers for expiration
Message: Checking peers for expiration
Message: Accepting peer 192.168.2.100
Message: Got command /usr/local/libexec/NoCatSplash/access.fw permit
00:2A:78:3D:58:A7 192.168.2.100 Public from action PermitCmd
Message: Captured peer 192.168.2.100
Message: Splashed peer 192.168.2.100
I created a splash.html:
</p>
<input type="hidden" name="redirect" value="$redirect">
<input type="hidden" name="accept_terms" value="yes">
<input type="hidden" name="mode_login">
<input type="submit" value="enter">
</form>
<p><img src="/images/auth_logo.gif" width="112" height="35">
<p>
Here's my nocat.conf file:
##########Nocat.conf file#############
Verbosity 10
##### Gateway application settings.
#
# GatewayName -- The name of this gateway, to be optionally displayed
# on the splash and status pages. Any short string of text will do.
#
GatewayName Trahersa NoCat Network
##
#
# GatewayMode -- Determines the mode of operation of the gateway. Possible
# values are:
#
# Open - Simply require a user to view a splash page and accept
# a use agreement.
#
# Only Open mode is currently supported.
#
GatewayMode Open
##
# GatewayLog -- Optional. If unset, messages will go to STDERR.
# (currently unused!)
#
# GatewayLog /var/log/nocat.log
##
# LoginTimeout - Number of seconds after a client's last
# login/renewal to terminate their connection. Probably
# don't want to set this to less than 60 or a lot of
# bandwidth is likely to get consumed by the client's
# renewal attempts.
#
# For Open Mode portals, you probably want to comment out
# the preceding and set LoginTimeout to
# something large (like 86400, for one notification
# per day).
#
LoginTimeout 86400
###### Open Portal settings.
#
##
# HomePage -- The authservice's notion of a default
# redirect.
#
HomePage http://nocat.net/
# DocumentRoot -- Where all of the application templates (including
# SplashPage) are hiding. Can be different from Apache's DocumentRoot.
# Defaults to /usr/local/share/NoCatSplash/htdocs via compile-time option.
#
# DocumentRoot /usr/local/share/NoCatSplash/htdocs
# SplashForm -- Form displayed to users on capture.
#
SplashForm splash.html
# StatusForm -- Page displaying status of logged in users.
# NOT YET IMPLEMENTED.
#
StatusForm status.html
# SplashURL -- URL to fetch remote splash page from. You must compile
# with --with-remote-splash for this to work. SplashTimeout specifies
# the reload period of the remote splash page.
#
# SplashURL http://example.com/get_splash_page.cgi?node=$NodeID
#
# SplashTimeout 21600
###### Active/Passive Portal settings.
# None of these settings affect open mode operation.
#
# TrustedGroups - A list of groups registered with the auth server
# that a user may claim membership in order to gain Member-class
# access through this portal. The default magic value "Any" indicates
# that a member of *any* group is granted member-class access from
# this gateway. NOT YET IMPLEMENTED.
#
# TrustedGroups NoCat NYCWireless PersonalTelco
#
TrustedGroups Any
##
# Owners - Optional. List all local "owner" class users here, separated
# by spaces. Owners typically get full bandwidth, and unrestricted
# access to all network resources. NOT YET IMPLEMENTED.
#
# Owners [email protected] [email protected]
##
# AuthServiceAddr - Required, for captive mode. Must be set to the
address of
# your authentication service. You must use an IP address
# if DNS resolution isn't available at gateway startup.
#
# AuthServiceAddr 208.201.239.21
#
AuthServiceAddr auth.nocat.net
##
# AuthServiceURL - HTTPS URL to the login script at the authservice.
#
AuthServiceURL https://auth.nocat.net/cgi-bin/login
##
# LogoutURL - HTTP URL to redirect user after logout.
#
LogoutURL https://auth.nocat.net/logout.html
##
# PGPKeyPath -- The directory in which PGP keys are stored.
# NoCat tries to find this in the pgp/ directory above
# the bin/ parent directory. Set this only if you put it
# somewhere that NoCat doesn't expect.
#
# PGPKeyPath /usr/local/share/NoCatSplash/pgp
### Network Topology
#
# FirewallPath - Where to find the firewall scripts.
# Defaults to /usr/local/libexec/NoCatSplash via compile-time option.
#
# FirewallPath /usr/local/libexec/NoCatSplash
#
# ExternalDevice - Required if and only if NoCatAuth can't figure it out
# from looking at your routing tables and picking the interface
# that carries the default route. Must be set to the interface
# connected to the Internet. Usually 'eth0' or 'eth1'
# under Linux, or maybe even 'ppp0' if you're running
# PPP or PPPoE.
#
ExternalDevice eth0
##
# InternalDevice - Required if and only if your machine has more than two
# network interfaces. Must be set to the interface connected to your local
# network, normally your wireless card.
#
InternalDevice eth1
##
# LocalNetwork - Required if and only if NoCatSplash can't figure it out
# by polling the InternalDevice. Must be set to the network
# address and net mask of your internal network. You
# can use the number of bits in the netmask (e.g. /16, /24, etc.)
# or the full x.x.x.x specification.
#
# LocalNetwork 10.0.1.0/24
LocalNetwork 192.168.2.0/24
##
# DNSAddr - Optional. *If* you choose not to run DNS on your internal
network,
# specify the address(es) of one or more domain name server on the
Internet
# that wireless clients can use to get out. Should be the same DNS
that your
# DHCP server hands out.
#
# DNSAddr 111.222.333.444
DNSAddr 196.3.81.5 200.88.127.22
##
# AllowedWebHosts - Optional. List any domains that you would like to
# allow web access (TCP port 80 and 443) BEFORE logging in (this is the
# pre-'skip' stage, so be careful about what you allow.)
#
# AllowedWebHosts nocat.net
##
# RouteOnly - Required only if you DO NOT want your gateway to act as a
NAT.
# Uncomment this only if you're running a strictly routed network, and
# don't need the gateway to enable NAT for you.
#
# RouteOnly 1
##
# MembersOnly - Optional. Uncomment this if you want to disable public
# access (i.e. unauthenticated 'skip' button access). You'll also want to
# point AuthServiceURL somewhere that doesn't include a skip button (like
# at your own Auth server.)
#
# MembersOnly 1
##
# IncludePorts - Optional. Specify TCP ports to allow access to when
# public class users login. All others will be denied.
#
# For a list of common services and their respective port numbers, see
# your /etc/services file. Depending on your firewall, you might even
# be able to specify said services here, instead of using port numbers.
#
# IncludePorts 22 80 443
##
# ExcludePorts - Optional. Specify TCP ports to denied access to when
# public class users login. All others will be allowed.
#
# Note that you should use either IncludePorts or ExcludePorts, but not
# both. If neither is specified, access is granted to all ports to
# public class users.
#
# You should *always* exclude port 25, unless you want to run an portal
# for wanton spam sending. Users should have their own way of sending
# mail. It sucks, but that's the way it is. Comment this out *only if*
# you're using IncludePorts instead.
#
# ExcludePorts 23 25 111
#
ExcludePorts 25
####### Syslog Options -- alter these only if you want NoCat to log to the
# system log! NOT YET IMPLEMENTED.
#
# Log Facility - syslog or internal. Internal sends log messages
# using the GatewayLog or STDERR if GatewayLog is unset. Syslog
# sends all messages to the system log.
#
# LogFacility internal
##
# SyslogSocket - inet or unix. Inet connects to an inet socket returned
# by getsrvbyname(). Unix connects to a unix domain socket returned by
# _PATH_LOG in syslog.ph (typically /dev/log). Defaults to unix.
#
# SyslogSocket unix
##
# SyslogOptions - Zero or more of the words pid, ndelay, cons, nowait
# Defaults to "cons,pid".
#
# SyslogOptions cons,pid
##
# SyslogPriority - The syslog class of message to use: In decreasing
importance,
# the typical priorities are EMERG, ALERT, CRIT, ERR, WARNING,
NOTICE, INFO,
# and DEBUG. Defaults to INFO.
#
# SyslogPriority INFO
##
# SyslogFacility - The facility used to log messages. Defaults to user.
# SyslogFacility user
##
# SyslogIdent - The ident of the program that is calling syslog. This will
# be prepended to every log entry made by NoCat. Defaults to NoCat.
#
# SyslogIdent NoCat
###### Other Common Gateway Options. (stuff you probably won't have to
change)
#
# ResetCmd, PermitCmd, DenyCmd -- Shell commands to reset,
# open and close the firewall. You probably don't need to
# change these.
#
# ResetCmd initialize.fw
# PermitCmd access.fw permit $MAC $IP $Class
# DenyCmd access.fw deny $MAC $IP $Class
##
# GatewayPort - The TCP port to bind the gateway
# service to. 5280 is de-facto standard for NoCatAuth.
# Change this only if you absolutely need to.
#
GatewayPort 5280
##
#
# IdleTimeout -- How often to check the ARP cache, in seconds,
# for expiration of idle clients. NOT YET IMPLEMENTED.
#
# MaxMissedARP -- How many times a client can be missing from
# the ARP cache before we assume they've gone away, and log them
# out. Set to 0 to disable logout based on ARP cache expiration.
#
MaxMissedARP 0
#
# IdleTimeout 300
### Fin!
Colin White wrote:
> Can't speak for nocatsplash but this was my approach for nocatauth...
>
> 1. Make sure your gpg is the same version on the gateway AND the
> access point. (I had to downgrade both versions of gpg).
>
> 2. Check location, ownership and file perms (600) of trustedkeys.gpg.
>
> 3. Set/sync system time/date on both the access point and gateway (if
> the system time is way out, you'll have problems with pgp keys).
>
> The mailing lists seems to suggest ~90% of login loops and redirect
> failures stem from key or certificate problems.
>
> 4. Turn on verbose logging on the AP and the gateway (from within the
> nocat.conf)
>
> 5. tail -f, the apache access and ssl-error logs as well as the nocat
> access point logs.
>
> 6. Test, tweak and retest, while watching the logs. Then post any
> logged error msgs back to this list.
> Good luck
>
> Rgds
> Colin
>
> On Mon, Nov 17, 2008 at 7:24 PM, Wilson Hernandez - MSD, S. A.
> <[email protected] <mailto:[email protected]>> wrote:
>
> Hello.
>
> I'm glad I found a mailing list for NoCat, hopefully there are
> still some users here.
>
> I've been trying to get configure nocatsplash for about a month
> now but, can't get it to work on a Etch. It captures the packet
> but it doesn't' redirect to the requested page. Can anyone help me
> with this please. Your assistance will be very appreciated.
>
> Thanks in advanced for your help.
>
> _______________________________________________
> NoCat mailing list
> [email protected] <mailto:[email protected]>
> http://lists.nocat.net/mailman/listinfo/nocat
>
>
>
>
> --
> Colin A. White
> P : +1 605 940 5863
>
>
--
*Wilson Hernandez*
Presidente
829.848.9595
809.766.0441
www.msdrd.com <http://www.msdrd.com>
Conservando el medio ambiente